Swiss company GDPR-compliant Servers in Germany
Angel Reminder Logo Angel Reminder

Home › Privacy

Privacy Policy

Last updated: July 2026

1. Controller

DigitalMove Consultants GmbH
Bösch 23
CH-6331 Hünenberg
Switzerland
E-Mail: [email protected]

2. Overview of Processing Activities

a) Account creation (free of charge)

During registration we collect:

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

b) Heartbeat system (premium feature)

Premium users configure a heartbeat interval. We store:

Purpose: Detecting whether the user is still reachable and triggering stored messages in a timely manner.

c) Stored messages and recipients

Users store:

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

d) Payment processing (Stripe)

For premium subscriptions (29 EUR/year) we use Stripe, Inc. (San Francisco, USA). Stripe processes payment data under its own responsibility. We receive from Stripe only:

Credit card details, bank details, or any other payment information are never stored on our servers.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in payment processing).
Recipient: Stripe, Inc. — Stripe's Privacy Policy.

e) Organ donor status (/donor/)

Users may voluntarily store their organ donor status with a 6-digit public key. This information is publicly accessible via /donor/<code>.

Legal basis: Art. 6(1)(a) GDPR (consent).

f) Server log data

When the website is accessed, the server automatically stores:

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring operation and security).
Retention: IP addresses are automatically deleted after 30 days.

g) E-mail communication

We send e-mails for:

Legal basis: Art. 6(1)(b) and (f) GDPR.

h) Messenger chat (premium feature)

Premium users who are mutually connected as trusted persons can use a 1:1 messenger (text messages and quick replies; audio/video calls will follow in a later phase). The messenger is enabled per connection (opt-in). We store:

Purpose: direct communication between connected trusted persons.
Legal basis: Art. 6(1)(b) GDPR (performance of the premium contract).
Retention: Messages are automatically deleted 90 days after being sent; on account deletion they are deleted immediately (see section 4).

Note on special categories (Art. 9 GDPR): In the current phase (Phase A), the chat text is stored on our servers in plain text; it is not end-to-end or zero-knowledge encrypted (such encryption is planned for a later phase). The messenger is intended for personal messages. As long as end-to-end encryption is not available, please do not enter special categories of personal data within the meaning of Art. 9 GDPR (in particular health data). Processing is based on Art. 6(1)(b) GDPR (processing of your own content within the scope of the contract); this note serves to manage the Art. 9 exposure.

i) Contact log (reachability / proof of life)

To operate the reachability / "dead man's switch" mechanism, we log messenger events (message sent, read, replied, push delivered) with timestamps. An active reply to a message resets the proof-of-life timer (heartbeat) of the person who originally sent it — in this respect the messenger acts as a sign of life.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the reliable operation of the reachability/trigger mechanism). You may object to this processing under Art. 21 GDPR; in that case we cannot provide the messenger for the affected connection.
Retention: Contact-log entries are automatically deleted after 90 days.

j) Web push notifications

On request, we send you push notifications about new messenger messages. For this we store the push credentials provided by your browser (endpoint URL and the keys p256dh and auth); these are personal data.

Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (the German Telecommunications Digital Services Data Protection Act, formerly TTDSG) / the ePrivacy Directive — consent. Consent is obtained via your browser's explicit permission prompt (not pre-checked) and can be withdrawn at any time (disable in your account or browser settings).
Third-country transfer: By its nature, web push is delivered via your browser vendor's push service (e.g. Google FCM, Apple, Mozilla), which may be located in a third country. The payload is end-to-end encrypted (RFC 8291); for chat notifications the displayed text is also kept generic (e.g. "You have a new message") — so no message content reaches the push service. We do not use any external push-relay provider (self-hosted VAPID).

k) Contracts and subscriptions (contract manager)

In the contract manager you can record running contracts and subscriptions: name, provider or contact, contract number, amount and payment interval, term, notice period and a free-text note (e.g. where the documents are kept). You decide yourself which of your recipients a contract is delivered to. All entries are free text – please do not store access credentials, passwords or complete payment details there.

Legal basis: Art. 6(1)(b) GDPR – performance of the user agreement concluded with you. Delivery to the recipients you name takes place solely on the instruction you gave in advance.
Note: If you enter special categories of personal data (Art. 9 GDPR) in the free-text note, this is based on your explicit consent under Art. 9(2)(a) GDPR.

3. Disclosure to Third Parties

Personal data is disclosed to third parties only:

4. Retention Periods

Data categoryRetention
Account data (e-mail, name)Until account deletion
Password hashUntil account deletion
Messages and recipientsUntil account deletion or dispatch
Messenger messages (chat)90 days after sending; immediately on account deletion
Contact log (messenger events)90 days
Web push credentials (endpoint, keys)Until notifications are withdrawn or account deletion
Contracts and subscriptions (contract manager)Until account deletion or deletion by you
Stripe subscription dataUntil 2 years after contract end
IP addresses30 days
Deleted accounts (soft-delete)Marked as inactive; data physically deleted after 90 days

5. Your Rights

Under the GDPR you have the right to:

Please direct requests to: [email protected]

6. Security

7. Cookies

We do not use tracking cookies. A technical session cookie may be used for the login process. No data is shared with third parties.

8. Changes

We reserve the right to update this Privacy Policy. The most current version is always available at this URL.

We compile the information on this website to the best of our knowledge and belief; even so, mistakes can never be ruled out entirely, and laws and practice change continuously. It is general in nature and replaces neither a review of your individual case nor professional advice — please check it yourself or ask a qualified professional before making a decision. We give no warranty as to accuracy, completeness or currency. Our liability under statutory provisions and our obligations under the contract for the Angel Reminder service remain unaffected.

Trust isn’t just a word here

Angel Reminder is a service by DigitalMove Consultants GmbH — a Swiss company. Your data is stored GDPR-compliant on servers in Germany, with no tracking and no sharing with ad networks.